Skip to content
Law Society of Scotland
Search
Find a Solicitor
Contact us
About us
Sign in
Search
Find a Solicitor
Contact us
About us
Sign in
  • For members

    • For members

    • CPD & Training

    • Membership and fees

    • Rules and guidance

    • Regulation and compliance

    • Journal

    • Business support

    • Career growth

    • Member benefits

    • Professional support

    • Lawscot Wellbeing

    • Lawscot Sustainability

    • Lawscot Tech

  • News and events

    • News and events

    • Law Society news

    • Blogs & opinions

    • CPD & Training

    • Events

  • Qualifying and education

    • Qualifying and education

    • Qualifying as a Scottish solicitor

    • Career support and advice

    • Our work with schools

    • Funding your education

    • Social mobility

  • Research and policy

    • Research and policy

    • Research

    • Influencing the law and policy

    • Equality and diversity

    • Our international work

    • Legal Services Review

    • Meet the Policy team

  • For the public

    • For the public

    • What solicitors can do for you

    • Making a complaint

    • Client protection

    • Find a Solicitor

    • Frequently asked questions

    • Your Scottish solicitor

  • About us

    • About us

    • Contact us

    • Who we are

    • Our strategy, reports and plans

    • Help and advice

    • Our standards

    • Work with us

    • Equality and diversity

Journal logo
  • PRACTICE

    PRACTICE

    • Practice

    • Corporate law

    • Criminal law

    • Employment law

    • Environment law

    • Family law

    • Industry updates

    • Intellectual property

    • Property law

    • Technology law

    • Technology and innovation

    • Practice

    • Corporate law

    • Criminal law

    • Employment law

    • Environment law

    • Family law

    • Industry updates

    • Intellectual property

    • Property law

    • Technology law

    • Technology and innovation

  • PEOPLE

    PEOPLE

    • People

    • Equality, diversity & inclusion

    • Ethics & professional responsibility

    • Obituaries

    • Wellbeing & support

    • Noticeboard

    • From the President's desk

    • People

    • Equality, diversity & inclusion

    • Ethics & professional responsibility

    • Obituaries

    • Wellbeing & support

    • Noticeboard

    • From the President's desk

  • CAREERS

    CAREERS

    • Careers

    • Job board

    • Leadership

    • Management

    • Skills

    • Training & education

    • Careers

    • Job board

    • Leadership

    • Management

    • Skills

    • Training & education

  • KNOWLEDGE BANK

    KNOWLEDGE BANK

    • Knowledge Bank

    • Book club

    • Interviews

    • Sponsored content

    • Next generation

    • The Future of Law on our High Streets

    • In-House – Behind the Scenes

    • Space — Scotland's Next Legal Frontier

    • Knowledge Bank

    • Book club

    • Interviews

    • Sponsored content

    • Next generation

    • The Future of Law on our High Streets

    • In-House – Behind the Scenes

    • Space — Scotland's Next Legal Frontier

  • ABOUT THE JOURNAL

    ABOUT THE JOURNAL

    • About the Journal

    • Contact us

    • Journal Editorial Advisory Board

    • Newsletter sign-up

    • About the Journal

    • Contact us

    • Journal Editorial Advisory Board

    • Newsletter sign-up

SPONSORED: AI Is Turbo-Charging Cyber Attacks. Is Your Law Firm Ready?

2nd April 2026 Written by: Mitigo

Artificial intelligence has changed the rules of cybercrime. Attacks that once required significant skill and resource can now be executed at scale, at speed and with unsettling precision.

Handling large amounts of sensitive client information makes law firms attractive targets for cybercriminals, with attacks on UK law firms surging by 77% in a single year.

And law firms are far from alone. Across UK sectors, the NCSC's Annual Review 2025 recorded a 130% increase in cyber incidents, identifying artificial intelligence as a key driver.

In a separate report, the NCSC warns that AI is already tipping the scales toward attackers by lowering the skill threshold needed to run sophisticated campaigns across any sector, shrinking the window between vulnerabilities being discovered and exploited.

Statistics like these make it clear that AI is accelerating cyber threats - and law firms must strengthen their defences.

How Criminals Are Using AI Against Law Firms

Phishing emails used to be easier to spot - poor grammar, odd phrasing, something slightly off. That is no longer the case. AI can now generate grammatically perfect, convincing messages that replicate the writing style of colleagues, partners or clients, complete with the right logos and tone. For law firms managing client correspondence and financial transactions, this significantly increases the risk of convincing payment diversion or email account takeovers.

Phishing is already the most common form of cyber attack facing firms. The UK Government's Cyber Security Breaches Survey 2025 found that 79% of UK businesses experienced phishing attacks, making it the most widely reported cyber incident. AI is making this method more effective, with AI-generated phishing achieving significantly higher click-through rates than human-crafted attacks.

Then there are deepfakes. In 2024, a finance worker transferred $25 million after a video call in which every participant - including the CFO - was a deepfake. For law firms, this tactic could easily target conveyancing, M&A or litigation teams who routinely authorise significant transfers under time pressure - a convincing deepfake posing as a client, lender or senior partner is all it takes.

The Repercussions Are Severe - And Most Law Firms Are Not Ready

A successful cyber attack doesn't just take down your systems. It can end your business.

The average cost of a data breach in the UK now stands at £3.29 million – before factoring in downtime, recovery costs, and reputational damage. For law firms, the regulatory exposure is compounded. The ICO can issue significant fines under GDPR Article 32, and the SRA expects firms to have robust data security measures in place - making it critical for firms to understand their exposure before an incident occurs.

Yet the gaps are stark. Only 19% of businesses have any cybersecurity training programme in place, and 78% have no incident response plan. Board-level responsibility for cyber risk has fallen to just 27% of organisations.

Too many firms assume their IT provider is managing this. They are not.

Cyber risk management and IT support are not the same thing - and firms that recognise this are the ones best placed to respond.

What You Need to Do

Cyber attacks are inevitable. What you do now is what matters. The right response comes down to three things: Assess your exposure, Act on the gaps, and Assure ongoing resilience.

  • Assess: Start with an independent risk assessment - covering people, processes and governance, not just technology. Your IT provider cannot do this objectively. With AI lowering the bar for attackers, gaps that once seemed minor are now critical for law firms.
  • Act: Build and test an incident response plan. If your firm suffered a cyber attack tomorrow – AI-driven or otherwise - would you survive? Furthermore, if your staff are using AI tools such as Copilot or ChatGPT, ensure clear policies are in place on what client data is being shared.
  • Assure: Board-level accountability is no longer optional - cyber risk is a leadership issue, not an IT one. Treat it as an ongoing discipline, not a one-off exercise. That means regular assessments, continuous oversight, and having a trusted cyber partner with specialist legal sector expertise.

Mitigo is the Law Society of Scotland’s strategic cyber risk management partner, helping firms across Scotland assess risk, close gaps and stay resilient.

Get in touch to strengthen your firm’s cyber resilience

Weekly roundup of Scots law in the headlines — Monday June 1

1st June 2026
Weekly roundup of Scots law in the headlines including ‘compelling evidence’ in Peter Murrell case – Monday June 1

Notice: Capita Group Proceedings — Court of Session

1st June 2026
Notice is hereby given that on 27 May 2026, the Court of Session made an order granting permission for group proceedings to be brought by Philip Mark Bull as representative party on behalf of members of the group against Capita PLC.

When an invoice is not a contract: the authorities behind the analysis

28th May 2026
"At the heart of the analysis was the principle that where a pursuer’s averments, supported by productions lodged in process, directly and compellingly contradict the defender’s position, the court is entitled to proceed on that basis."
About the author
Add To Favorites

Additional

https://lawware.co.uk
https://yourcashier.co.uk/

Related Articles

Weekly roundup of Scots law in the headlines — Monday June 1

1st June 2026
Weekly roundup of Scots law in the headlines including ‘compelling evidence’ in Peter Murrell case – Monday June 1

Weekly roundup of Scots law in the headlines — Monday May 25

25th May 2026
Weekly roundup of Scots law in the headlines including top law officer stepping down – Monday May 25

Gender, society and the law — Telling the history of Scotland through 15 violent crimes

22nd May 2026
An intriguing new book explores the reactions of society and the law to violence, from the role of gender through...

Journal issues archive

Find all previous editions of the Journal here.

Issues about Journal issues archive
Law Society of Scotland
Atria One, 144 Morrison Street
Edinburgh
EH3 8EX
If you’re looking for a solicitor, visit FindaSolicitor.scot
T: +44(0) 131 226 7411
E: [email protected]
About us
  • Contact us
  • Who we are
  • Strategy reports plans
  • Help and advice
  • Our standards
  • Work with us
Useful links
  • Find a Solicitor
  • Sign in
  • CPD & Training
  • Rules and guidance
  • Website terms and conditions
Law Society of Scotland | © 2026
Made by Gecko Agency Limited